What is CVE-2026-19983?
This vulnerability exists in the NAS Command Service component of GL.iNet routers, allowing OS command injection via the /usr/bin/gl_nas_sys file. Affected devices include A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 models. Users should immediately apply the vendor-released security update and isolate the device from untrusted networks.
Azərbaycanca: Bu boşluq GL.iNet rouderlərinin NAS Command Service komponentindədir və /usr/bin/gl_nas_sys faylındakı zəiflik vasitəsilə əmr inyeksiyasına imkan verir. Təsirə məruz qalan cihazlar A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 və XE3000 modellərini əhatə edir. İstifadəçilər dərhal istehsalçının yayımladığı təhlükəsizlik yeniləməsini tətbiq etməli və cihazı etibarsız şəbəkələrdən izolyasiya etməlidir.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: GL.iNet
FAQ2
Which component of GL.iNet routers is affected by CVE-2026-19983?
This vulnerability is in the NAS Command Service component of GL.iNet routers.
What should users do immediately to mitigate the CVE-2026-19983 vulnerability?
Users should immediately apply the vendor-released security update and isolate the device from untrusted networks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.